Is Your API Ready for AI Agents? A 6-Point Checklist: llms.txt, agent-card.json, MCP Server Card, ai-catalog.json, robots.txt, x402
Audit your domain for AI agents in ten minutes: six pass/fail curl checks for llms.txt, A2A agent-card.json, MCP, ARD ai-catalog.json, robots.txt and x402.
AI agents from Claude, ChatGPT, and Gemini now find and call services without a human pasting in a URL. They do that by reading a handful of files and endpoints on your domain. If those are missing, or present but broken, the agent moves on to a competitor whose files work.
This is a self-audit. Six checks, each with a curl command and a clear pass condition. For background on what each file is and why it exists, the longer guide is How to Make Your Website Discoverable to AI Agents; this post is the pass/fail version.
Replace example.com with your domain and run each command from a machine outside your network.
Check 1: llms.txt
curl -si https://example.com/llms.txt | head -20
Pass: 200, content-type: text/plain (or text/markdown), and a body that starts with a # Your Product heading followed by a one-line description and linked sections.
Common fail: your SPA returns index.html with a 200. The status looks fine and the body is HTML. Check the first line of the body, not just the status.
Quick fix: a Markdown file at your site root with your product name, a sentence naming what you do, and links to docs and pricing. Name specific entities (frameworks, providers, protocols) because that's what answer engines index.
Check 2: A2A Agent Card (if you expose an agent)
curl -si https://example.com/.well-known/agent-card.json
Pass: 200, application/json, valid JSON with a name, a service URL, and a non-empty skills array whose descriptions say what the agent does in concrete terms.
Common fails: the old card path (the spec's location has moved once, so check which your client expects), JSON syntax errors, and a card whose endpoint returns 404. A card that points at nothing is worse than no card. Skip this check if you don't operate an agent. Field-by-field details are in A2A Agent Cards Explained.
Check 3: MCP Endpoint and Server Card (if you expose tools)
Test that the endpoint answers an initialize request:
curl -si -X POST https://example.com/mcp \
-H 'content-type: application/json' \
-H 'accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"probe","version":"0"}}}'
Then check for the server card:
curl -si https://example.com/.well-known/mcp/server-card
Pass: either a 200 JSON-RPC result with serverInfo, or a 401 carrying a WWW-Authenticate header that points to OAuth protected resource metadata. A correct auth challenge counts as a pass because it tells clients exactly how to get in. The server card is optional and experimental (SEP-2127) but cheap to publish.
Common fail: a 401 with no usable header. If your server is auth-protected and clients can't connect, see MCP Server Returns 401?.
Check 4: ARD Catalog
curl -si https://example.com/.well-known/ai-catalog.json
Pass: 200, JSON, and entries that list each agentic capability on your domain (your A2A agent, your MCP server) with a type and descriptive tags. The catalog is the index registries crawl, so every capability from checks 2 and 3 should appear here. Background: the ARD specification.
Common fail: the catalog lists an endpoint that no longer exists, or omits the MCP server you ship.
Check 5: robots.txt — Agentmap Line and Crawler Access
curl -s https://example.com/robots.txt
Pass, part one: it contains an Agentmap: directive pointing to your catalog:
Agentmap: https://example.com/.well-known/ai-catalog.json
Pass, part two: it doesn't block the crawlers you want to reach you. Look for Disallow: / under user agents such as GPTBot, ClaudeBot, Google-Extended, PerplexityBot, or CCBot. Blocking some of these is a legitimate policy choice for training data, but a blanket User-agent: * / Disallow: / copied from a staging config will hide your discovery files from everything. Make the choice deliberately.
Check 6: x402 Payment Challenge (if you charge per request)
If your API is paid per call, agents need to know the price before they send money. The x402 protocol does this with an HTTP 402 Payment Required response:
curl -si https://example.com/api/paid-endpoint
Pass: 402 with a machine-readable payment requirements body naming the network, asset, amount, and payTo address, and nothing ambiguous an agent has to guess at. Skip this check if your API is free or uses conventional API keys. To validate the challenge itself, use x402 Inspector; the pre-payment checks an agent should run are in the x402 payment checklist.
Scoring Yourself
| Passes (of the checks that apply) | Where you stand |
|---|---|
| All | Discoverable and callable. Re-check quarterly. |
| Checks 1 and 5 only | Crawlable by answer engines, invisible to agent registries. Add the protocol files that match what you ship. |
| Protocol files present, check 5 fails | Files exist but registries won't find them. Add the Agentmap line, fix crawler rules. |
Any 200 returning HTML | A catch-all route is masking failures. Fix this first. |
Check only the items that match what you actually offer. Publishing a card or catalog entry for a capability you don't run creates a trap for agents.
Do the Whole Sweep in One Scan
The six curl checks take about ten minutes by hand and need repeating whenever you change your CDN or routing rules. Agent Readiness Detector runs the protocol checks in one scan: agent card, ARD catalog, robots.txt Agentmap line, MCP initialize handshake, and MCP discovery metadata. It reports each protocol as confirmed, indicated, or not detected, with the evidence lines behind each verdict. llms.txt and the x402 challenge are the two checks you run separately with the commands above.
Run it from the outside, because that's where agents sit.
Follow Trango Compute on LinkedIn
We post updates on new tools, context engineering patterns, and LLM cost research.